Data Protection Policy

Policy Statement

RBGE collects and uses information about people, including:

  • Staff, volunteers and applicants for jobs and voluntary posts
  • Supporters, visitors, donors, and enquirers
  • Students and researchers

This personal information will be managed appropriately and securely - however it is collected, recorded, and used, whether on paper or digitally– in compliance with the Data Protection Act 2018 (DPA) and the General Data Protection Regulation (GDPR).

The purpose of this policy is to ensure that RBGE has robust procedures in place for demonstrable compliance with GDPR/DPA. 

Breaching this policy may result in disciplinary action for misconduct, including dismissal. Obtaining (including accessing) or disclosing personal data in breach of RBGE’s data protection policies may also be a criminal offence.

Principles

Data users must comply with the data protection principles. Whenever RBGE works with personal data it will be: 

  • processed fairly, lawfully, and transparently (see RBGE Privacy Notice)
  • collected for specific purposes and not used for incompatible purposes
  • adequate, relevant, and limited to what is necessary
  • accurate and, where necessary, kept up to date
  • retained no longer than necessary (see RBGE Records Retention Schedule)
  • kept securely

The principles apply to “personal data” - any information from which an individual is identifiable. 

RBGE staff, volunteers, and contractors who process or use any personal information in the course of their work must ensure that these principles are always followed. The member of staff responsible for the contractor must ensure these principles are adhered to.

Responsibilities

Senior Information Risk Owner (SIRO) — RBGE’s Director of Learning & Engagement has specific senior responsibility for data protection within RBGE.

The Records Management Working Group, under the leadership of the Director of Learning & Engagement, oversees RBGE’s records management policies, procedures, and compliance. This group also acts as a forum for raising awareness of data protection issues and discussing requirements.

Information Asset Owners (IAOs) are senior or responsible individuals who oversee specific business areas within the organisation. Their main responsibility is to ensure that all information assets under their control are managed appropriately in line with organisational requirements. IAO’s are tasked with monitoring both risks and opportunities associated with these information assets, thereby safeguarding the integrity and utility of the organisation’s information.

It is important that IAOs ensure all staff who process personal data on their behalf have completed regular data protection training. This commitment helps maintain compliance and supports robust data governance across the organisation.

Each IAO has responsibility for ensuring that the information they oversee is collected, processed, and held in accordance with this policy and the General Data Protection Regulation (GDPR). Furthermore IAOs must maintain an accurate and current description of all personal information assets for which they are accountable in the RBGE processing activities log.

The Data Protection Officer (DPO) advises and oversees RBGE’s GDPR compliance, serving as the point of contact for data subjects and the Information Commission (IC). The DPO is also a member of the Records Management Working Group. The DPO can be contacted via DPO@rbge.org.uk.

All RBGE staff, volunteers, students and any contractors or agents performing work for or on behalf of RBGE and any other individuals with access to RBGE’s information:

  • Are responsible for protecting personal information at all times. This means only using personal data as authorised in compliance with this policy and other digital and information security policies.
  • Must promptly notify the DPO if they notice or suspect any incident that could affect the confidentiality, integrity or availability of personal data held by RBGE.
  • Should complete data protection training as soon as it is requested. If you have any questions about data protection training, please contact DPO@rbge.org.uk

Processing personal data at RBGE

RBGE collects and processes personal data for a range of legitimate purposes, including

  • Recruitment and selection
  • Administration of contracts of employment e.g., salaries and allowances, pensions and associated benefits, appraisal, training and development, compliance with statutory requirements - Employee Privacy Notice
  • Financial information (e.g., bank account details and credit card information)
  • Health and safety compliance including safeguarding
  • Management of volunteers
  • Management of students - Education Privacy Notice
  • Marketing, promotion, and fundraising activities - Development Privacy Notice
  • Administration of collections information (e.g., donors, vendors, loans)
  • Identification, including library user records and staff photographs
  • Membership records, contacts, databases and mailing lists
  • Contacts management for collaborative research 
  • CCTV monitoring to ensure public safety and preventor detect criminal activity
  • Analysis of visitor audiences and engagement

All staff, volunteers, and contractors working under the authority of RBGE are required to access and use personal data only in accordance with this policy and for specifically for authorised purposes.  Network usernames and passwords must be kept confidential, and information systems should be used strictly in line with relevant procedures and training guidelines. 3.13 IT Systems Acceptable Usage Policy - RBGE Green Pages.

Retention of Data

Personal data must not be retained for longer than is necessary. RBGE IAO’s and managers are responsible for ensuring that the Record Retention Schedule is applied to all records and documents holding personal data, by having regular or automated deletion or destruction of personal data in systems, paper files and on network folders.

All documents containing personal data should be disposed of in a secure manner in accordance with the Data Protection principles.

Transfer of Personal Data

All mobile devices or digital media such as a laptop, mobile phone, tablet, or USB memory device holding personal data or used for processing RBGE personal data, whether that device is RBGE or privately owned, must be encrypted. Further guidance for staff can be found in Green Pages: Cyber Security & Data Protection - RBGE Green Pages.

If you need to send personal information by email then please read the guidance on protecting documents for sending by email on Green Pages.

Personal data rights

RBGE is committed to upholding individuals' rights regarding their personal data. The rights provided under GDPR include:

  • The right to be informed that processing is being undertaken (GDPR articles 13 and 14)
  • The right of access to one's own personal data and to specific information about the processing (article 15) – ‘Subject Access Request Information’
  • The right to object to and prevent processing in certain circumstances (article 21)
  • The right to rectify or restrict inaccurate data (articles 16 and 18)
  • The right to erase data or to data portability in certain circumstances (articles 17 and 20)

All inquiries or requests concerning GDPR rights should be directed to the Data Protection Officer at DPO@rbge.org.uk

Personal data incidents and breaches

All staff should immediately notify the DPO via email or phone and complete the Data Breach form available on Green Pages. If you are unsure whether an incident qualifies, contact the DPO for guidance.

Examples of data breaches may include:

  • Loss or theft of RBGE records, laptops, or other storage media containing personal data
  • Unauthorised access to RBGE information systems, whether internal or external
  • Personal data being sent to the wrong recipient, such as an email containing sensitive information mistakenly addressed to an unintended party
  • Accidental or deliberate alteration or deletion of personal data without proper authorisation
  • Failure to securely dispose of documents or devices containing personal information, resulting in potential exposure
  • Disclosure of personal data to individuals who do not have a legitimate reason to receive it

The DPO will document the incident, ensure the proper mitigation actions are taken and assess whether the incident meets the GDPR definition of a personal data breach that could pose a risk to individuals.

A report will then be submitted by the DPO to the SIRO. This report may include a recommendation on whether the breach needs to be reported to the IC within 72 hours of RBGE's awareness of the incident.

If the SIRO decides the incident is indeed a reportable breach, the DPO will notify the IC and manage any necessary communication.

Governance of Data Protection

RBGE ensures transparent and thorough management of personal data by maintaining:

  • Current privacy notices (articles 13 and 14 of GDPR)
  • A processing activities log detailing purpose, controls, and responsible staff for each data system or set of records holding personal data
  • A log of information security incidents
  • Regular training on information security

RBGE will apply ‘Privacy by Design’ principles for new systems and business processes. This means that privacy and data protection will be a key consideration in the early stages of any project, and then throughout its lifecycle. Taking a privacy by design approach will help minimise privacy risks and will build trust.  As appropriate, the relevant Information Asset Owner may be asked to complete a Data Protection Impact Assessment (DPIA) in line with a template and guidance from the IC.

All contracts with organisations processing personal data on behalf of RBGE (data processors) will have GDPR-compliant contract clauses and be subject to appropriate levels of review and oversight.

All RBGE staff and volunteers will receive training and awareness-raising on data protection and information security relevant to their role.

For personal data processed for electronic direct marketing purposes (e.g. newsletters and other promotional materials sent by email or text message) RBGE will only use contact details for private individuals where the person has explicitly opted-in (consented) to receive such communications from RBGE.

How to complain

If you are concerned about how we use your personal information, you can send a complaint to us at DPO@rbge.org.uk

If you are not satisfied with our response or how we have handled your data, you also have the option to contact the Information Commissioner. The IC’s address:  

Information Commission

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

Helpline number: 0303 123 1113

IC website: https://www.ico.org.uk 

 

People & OD

Review Date:                          May 2026

Planned Review Date:           May 2029

Discover more

Back to Corporate Policies

Sign-up to our newsletter